CVE-2004-0323
Summary
| CVE | CVE-2004-0323 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in stats.php. NOTE: it has also been shown that item (3) is also in XMB 1.9 beta. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| XMB Forum Multiple Input Validation Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch |
| '[waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| archives.neohapsis.com/archives/bugtraq/2004-02/0645.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| Security Issue History - XMBdocs | af854a3a-2127-422b-91ae-364da2661108 | docs.xmbforum2.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.xmbforum.com/community/boards/viewthread.php | af854a3a-2127-422b-91ae-364da2661108 | www.xmbforum.com | |
| Neohapsis Archives - Bugtraq - #0265 - [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 SP3 and 1.9 beta] | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| XMB | 2008-12-11 | XMB versions 1.9.8 SP2 and later were checked and are not vulnerable. |
There are currently no legacy QID mappings associated with this CVE.